Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Ford explores decentralized legal data storage on Cardano blockchain

June 19, 2025

PancakeSwap extends lead as monthly DEX volume tops $500B

June 19, 2025

Crypto Giant a16z Recovers X Account After Hackers Push Fraudulent $a16z Token

June 19, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    ‘Ancient’ Bitcoin Supply Now Outpacing Newly Mined BTC: Fidelity Report

    June 19, 2025

    Bitcoin, Ethereum, and XRP Price Today (19th June, 2025)

    June 19, 2025

    This Bitcoin Investor Cohort Locked in $904,000,000 in Realized Gains, Driving BTC Sell Pressure, According to Analytics Firm Glassnode

    June 19, 2025

    Uniswap’s UNI Token Extends Recovery as Buyers Defend $7.14 Support

    June 19, 2025

    Is Ethereum Price Set To Repeat History As 2017 Playbook Returns? Why This Time Could Be Bigger

    June 19, 2025

    Ethereum: $500M shorts wiped, bulls poised – Can ETH retain its stride?

    June 19, 2025

    Here Is the Main Reason Why Ethereum Price Remains Choppy Amid High Spot ETF Demand

    June 19, 2025

    Ethereum Golden Cross Approaching – Will History Repeat?

    June 19, 2025

    Solana: 386K SOL sold in 4 days – Traders, watch THESE levels next

    June 19, 2025

    Dogecoin (DOGE) Struggles to Climb — Upside Moves Likely to Face Strong Resistance

    June 19, 2025

    What happens to Bitcoin if the U.S. joins the Iran-Israel war?

    June 19, 2025

    She Turned $500 into $114k with Ethereum—Now This Presale Star Is Her 100x Pick for 2025

    June 18, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Ford explores decentralized legal data storage on Cardano blockchain

    June 19, 2025

    PancakeSwap extends lead as monthly DEX volume tops $500B

    June 19, 2025

    Crypto Giant a16z Recovers X Account After Hackers Push Fraudulent $a16z Token

    June 19, 2025

    Is Ethereum Price Set To Repeat History As 2017 Playbook Returns? Why This Time Could Be Bigger

    June 19, 2025
  • DeFi

    PancakeSwap extends lead as monthly DEX volume tops $500B

    June 19, 2025

    Ethena Labs and Securitize enable 24/7 USDtb-BUIDL swaps

    June 19, 2025

    Canada-based AgriFORCE launches Bitcoin mining site powered by stranded gas

    June 19, 2025

    Spark crypto price crashes despite key metric hitting a record high

    June 19, 2025

    XRP could be gearing up for a major rally despite weak ETF reaction

    June 18, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Crypto Giant a16z Recovers X Account After Hackers Push Fraudulent $a16z Token

    June 19, 2025

    UNICEF and Bitget crypto exchange to advance blockchain literacy globally

    June 19, 2025

    Iran Limits Crypto Trading Hours After Pro Israel Hackers Hit Top Domestic Exchange

    June 19, 2025

    Warning to builders: L2s are leaking value, L1 appchains are the smarter bet

    June 19, 2025

    Israeli Hacktivists Steal and Burn $90m+ from Iranian Crypo Biz

    June 19, 2025

    ZachXBT warns suspected ZKasino fraudster may be linked to new crypto venture WhiteRock

    June 17, 2025

    Threat Actors Target Victims with HijackLoader and DeerStealer

    June 17, 2025

    Coinbase data breach spills offline as victims get scam mail

    June 6, 2025

    Ford explores decentralized legal data storage on Cardano blockchain

    June 19, 2025

    PancakeSwap extends lead as monthly DEX volume tops $500B

    June 19, 2025

    Crypto Giant a16z Recovers X Account After Hackers Push Fraudulent $a16z Token

    June 19, 2025

    Is Ethereum Price Set To Repeat History As 2017 Playbook Returns? Why This Time Could Be Bigger

    June 19, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    ReggaeEDM Takes The Stage | Web3Wire

    June 19, 2025

    Future of Predictive Corrosion Management Market Size US$ 2,319.88 Mn by 2032 : Key Players & Forecast | Japan Insights

    June 19, 2025

    Website Security Software Market Size & Trends Estimation: Norton, McAfee, Cloudflare, Sucuri, Akamai

    June 19, 2025

    QBI Token Leads the Digital Engine of AI and Fintech Integration: Quantivision Business Institute Takes a Key Step in Global Cloud Deployment

    June 19, 2025

    Floki’s Valhalla Fires Up 4-Week Programmatic Display Push Across Target Markets

    June 19, 2025

    Pudgy Penguins launches Pengu Clash on the TON blockchain

    June 19, 2025

    Floki’s Valhalla to Launch 4-Week Reddit Blitz Ahead of Mainnet Release

    June 18, 2025

    Web3 Game My Neighbour Alice Launches on Chromia Blockchain

    June 18, 2025

    Ford explores decentralized legal data storage on Cardano blockchain

    June 19, 2025

    PancakeSwap extends lead as monthly DEX volume tops $500B

    June 19, 2025

    Crypto Giant a16z Recovers X Account After Hackers Push Fraudulent $a16z Token

    June 19, 2025

    Is Ethereum Price Set To Repeat History As 2017 Playbook Returns? Why This Time Could Be Bigger

    June 19, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    South Korea moves closer to spot Bitcoin ETFs as FSC explores proposal

    June 19, 2025

    Legal Expert Reveals Why the SEC vs Ripple Case Should Still Be Relevant to XRP Investors

    June 19, 2025

    Gemini accuses CFTC of unfair legal campaign in formal complaint

    June 19, 2025

    Thailand exempts Bitcoin, crypto gains from tax to support entrepreneurs and innovation

    June 19, 2025

    Ford explores decentralized legal data storage on Cardano blockchain

    June 19, 2025

    Two public firms announce plans to adopt HYPE as primary reserve asset for treasury

    June 19, 2025

    Ohio passes blockchain bill allowing $200 tax-free Bitcoin payments

    June 18, 2025

    JPMorgan pilots tokenized deposit token on Base, targeting instant dollar transfers

    June 18, 2025

    Ford explores decentralized legal data storage on Cardano blockchain

    June 19, 2025

    PancakeSwap extends lead as monthly DEX volume tops $500B

    June 19, 2025

    Crypto Giant a16z Recovers X Account After Hackers Push Fraudulent $a16z Token

    June 19, 2025

    Is Ethereum Price Set To Repeat History As 2017 Playbook Returns? Why This Time Could Be Bigger

    June 19, 2025
  • Analysis

    Why Is Cardano (ADA) Price Dropping Today? Here’s What You Need to Know!

    June 19, 2025

    Goldman Sachs Flips Bullish on Ten Stocks – Bank Says These Companies Could Be China’s ‘Magnificent 7’

    June 19, 2025

    JPMorgan Chase Meets With Crypto Task Force to Discuss Regulation of Digital Assets

    June 19, 2025

    XRP network activity surges as Canada launches an XRP ETF

    June 18, 2025

    Arthur Hayes Sounds Alarm on Emerging ‘Stablecoin Mania,’ Warns of Potential Repeat of Terra Luna’s $40,000,000,000 Collapse

    June 18, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    Coinbase launches stablecoin payment stack with USDC checkout targeting commerce giants

    June 19, 2025

    Circle’s USDC and BlackRock’s BUIDL spearhead collateral innovation in derivatives markets

    June 19, 2025

    Kraken’s L2 network rolls out native INK token to power protocol incentives, allocation

    June 18, 2025

    Coinbase seeking SEC approval to offer blockchain-based equities

    June 18, 2025

    Ford explores decentralized legal data storage on Cardano blockchain

    June 19, 2025

    PancakeSwap extends lead as monthly DEX volume tops $500B

    June 19, 2025

    Crypto Giant a16z Recovers X Account After Hackers Push Fraudulent $a16z Token

    June 19, 2025

    Is Ethereum Price Set To Repeat History As 2017 Playbook Returns? Why This Time Could Be Bigger

    June 19, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Cryptomining Malware Found in Popular Open Source Packages
Cryptomining Malware Found in Popular Open Source Packages
Security and Privacy

Cryptomining Malware Found in Popular Open Source Packages

December 24, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A recent string of high-profile compromises has brought to light the growing threat of malicious code infiltration in popular open source packages. Security researchers at ReversingLabs uncovered breaches in rspack, a JavaScript bundler, and vant, a Vue UI library for mobile web apps, both widely downloaded from npm, a major package manager.

The compromised versions of @rspack/core and @rspack/cli (1.1.7) and vant (2.13.3 to 4.9.14) were found to contain cryptomining malware, specifically the XMRig cryptominer. Thankfully, maintainers quickly removed the tainted packages and released clean versions (rspack 1.1.8 and vant 4.9.15) to mitigate the risk to users.

These incidents are part of a concerning trend in open source software compromises. Recent attacks on @lottiefiles/lottie-player, a Solana blockchain library, and the ultralytics Python package have highlighted the vulnerabilities within the open source ecosystem. Malicious actors have been utilizing stolen npm tokens, GitHub Actions Script Injection, and stolen PyPI API tokens to infiltrate popular packages and distribute malware.

Differential analysis has been instrumental in detecting these breaches, allowing researchers to compare clean and malicious versions to identify suspicious code and behaviors. Lucija Valentić, a software threat researcher at ReversingLabs, emphasized the importance of using differential policies to detect known software supply chain attacks proactively.

To prevent future compromises, it is essential for developers to implement strict access controls, regularly scan software dependencies for vulnerabilities, and use automated tools to monitor for any suspicious activity in package updates. By taking a proactive approach to security, the open source community can better protect users from the growing threat of malicious code infiltration.

See also  US, Japan and South Korea Unite to Counter North Korean Cyber Activiti
CryptoMining Malware open Packages Popular source
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Israeli Hacktivists Steal and Burn $90m+ from Iranian Crypo Biz

June 19, 2025

ZachXBT warns suspected ZKasino fraudster may be linked to new crypto venture WhiteRock

June 17, 2025

Threat Actors Target Victims with HijackLoader and DeerStealer

June 17, 2025

Bitcoin vs. Open Interest – Should traders be worried by THIS divergence?

June 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bitcoin (BTC) Eyes $78,500, Bearish Pattern Signals Trouble

March 29, 2025

Bitcoin Price Dives Once More—Is a Deeper Correction Underway?

March 10, 2025

RWAfi platform Plume secures $20m Series A round

December 19, 2024
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Ford explores decentralized legal data storage on Cardano blockchain

June 19, 2025

PancakeSwap extends lead as monthly DEX volume tops $500B

June 19, 2025

Crypto Giant a16z Recovers X Account After Hackers Push Fraudulent $a16z Token

June 19, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.